Threat actors started actively scanning for the Microsoft Exchange ProxyShell remote code execution flaws. ProxyShell is the name of three vulnerabilities that could be chained by an unauthenticated remote attacker to gain code execution on Microsoft Exchange servers.
The vulnerabilities are exploited remotely through Microsoft Exchange’s Client Access Service (CAS) running on port 443 in IIS.
Microsoft has issued an update to correct this vulnerability. More details can be found at: